GHSA-jgqf-hwc5-hh37
Dashboard / Vulnerabilities / GHSA-jgqf-hwc5-hh37
Summary: Root Path Disclosure in send
Details: Versions of `send` prior to 0.11.2 are affected by an information leakage vulnerability which may allow an attacker to enumerate paths on the server filesystem. ## Recommendation Update to version 0.11.1 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-8859, https://github.com/pillarjs/send/pull/70, https://github.com/pillarjs/send/commit/98a5b89982b38e79db684177cf94730ce7fc7aed, https://github.com/expressjs/serve-static/blob/master/HISTORY.md#181--2015-01-20, https://github.com/pillarjs/send, https://web.archive.org/web/20200227192016/https://www.securityfocus.com/bid/96435, http://www.openwall.com/lists/oss-security/2016/04/20/11
Affected packages
Package
Name: send
Purl: pkg:npm/send
Affected ranges
Type: SEMVER
Events:
